CVE-2021-32760
Summary
| CVE | CVE-2021-32760 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-07-19 21:15:00 UTC |
| Updated | 2024-01-31 13:15:00 UTC |
| Description | containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host’s filesystem. Changes to file permissions can deny access to the expected owner of the file, widen access to others, or set extended bits like setuid, setgid, and sticky. This bug does not directly allow files to be read, modified, or executed without an additional cooperating process. This bug has been fixed in containerd 1.5.4 and 1.4.8. As a workaround, ensure that users only pull images from trusted sources. Linux security modules (LSMs) like SELinux and AppArmor can limit the files potentially affected by this bug through policies and profiles that prevent containerd from interacting with specific files. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Release containerd 1.5.4 · containerd/containerd · GitHub |
MISC |
github.com |
|
| Archive package allows chmod of file outside of unpack target directory · Advisory · containerd/containerd · GitHub |
CONFIRM |
github.com |
|
| Release containerd 1.4.8 · containerd/containerd · GitHub |
MISC |
github.com |
|
| containerd: Multiple Vulnerabilities (GLSA 202401-31) — Gentoo security |
|
security.gentoo.org |
|
| [SECURITY] Fedora 34 Update: containerd-1.5.5-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: containerd-1.5.5-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159320 Oracle Enterprise Linux Security Update for containerd (ELSA-2021-9373)
- 159382 Oracle Enterprise Linux Security Update for containerd (ELSA-2021-15790)
- 179858 Debian Security Update for containerd (CVE-2021-32760)
- 198433 Ubuntu Security Notification for containerd vulnerabilities (USN-5012-1)
- 281850 Fedora Security Update for containerd (FEDORA-2021-53ce601cb0)
- 352492 Amazon Linux Security Advisory for containerd: ALAS-2021-1523
- 353049 Amazon Linux Security Advisory for containerd : ALAS2NITRO-ENCLAVES-2021-010
- 353062 Amazon Linux Security Advisory for containerd : ALAS2DOCKER-2021-010
- 356890 Amazon Linux Security Advisory for containerd : ALAS2ECS-2023-029
- 501538 Alpine Linux Security Update for containerd
- 501828 Alpine Linux Security Update for containerd
- 504642 Alpine Linux Security Update for containerd
- 6140358 AWS Bottlerocket Security Update for containerd (GHSA-786q-rjmj-cj3g)
- 671467 EulerOS Security Update for docker-engine (EulerOS-SA-2022-1424)
- 671480 EulerOS Security Update for docker-engine (EulerOS-SA-2022-1445)
- 671504 EulerOS Security Update for docker-engine (EulerOS-SA-2022-1501)
- 671542 EulerOS Security Update for docker-engine (EulerOS-SA-2022-1482)
- 671845 EulerOS Security Update for docker-engine (EulerOS-SA-2022-1886)
- 671881 EulerOS Security Update for docker-engine (EulerOS-SA-2022-1926)
- 710846 Gentoo Linux containerd Multiple Vulnerabilities (GLSA 202401-31)
- 750853 OpenSUSE Security Update for containerd (openSUSE-SU-2021:2412-1)
- 750893 OpenSUSE Security Update for containerd (openSUSE-SU-2021:1081-1)
- 751272 SUSE Enterprise Linux Security Update for containerd, docker, runc (SUSE-SU-2021:3506-1)
- 751273 OpenSUSE Security Update for containerd, docker, runc (openSUSE-SU-2021:3506-1)
- 751303 OpenSUSE Security Update for containerd, docker, runc (openSUSE-SU-2021:1404-1)
- 900212 CBL-Mariner Linux Security Update for moby-containerd 1.4.4
- 901088 Common Base Linux Mariner (CBL-Mariner) Security Update for moby-containerd (6680-1)
- 903386 Common Base Linux Mariner (CBL-Mariner) Security Update for moby-containerd (4610)
- 980391 Go (go) Security Update for github.com/containerd/containerd (GHSA-c72p-9xmj-rx3w)